coinpaprika-api

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions include adding an external Model Context Protocol (MCP) server (https://mcp.coinpaprika.com/sse) and installing a plugin via a marketplace command. These operations connect the agent to services provided by a well-known cryptocurrency data platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes unstructured data from external API responses, such as coin descriptions, search results, and event listings, which provides a surface for indirect prompt injection.
  • Ingestion points: Data returned by tools such as getCoinById, search, and getCoinEvents from the mcp.coinpaprika.com server.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the provided skill text.
  • Capability inventory: The skill allows the agent to query a wide range of market and coin metadata via 29 specialized MCP tools.
  • Sanitization: No sanitization or filtering logic is specified for the text content received from the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:46 PM